DevelopersConnect AI assistants with MCP
Connect AI assistants with MCP
Connect Grok Bot, ChatGPT, Claude, Cursor or your own AI app to DoorOps with OAuth and your existing company permissions.
DoorOps lets compatible AI assistants read records and prepare operational changes through a remote Model Context Protocol (MCP) connection. You sign in as yourself; your company, role, enabled features and normal business rules still apply.
Connection address
https://doorops.com/mcp/connect
Use Streamable HTTP with OAuth. Copy your connection address from Settings → Connect an AI agent. The shared address connects to the company you authorise and stays pinned to it. A company's own https://{your-org}.doorops.com/mcp address also works. Use a separate authorised connection for another company.
Your DoorOps company needs MCP access enabled, and you need permission for the task. Your AI provider's plan and workspace policy must also permit custom connections. A DoorOps subscription does not include another provider's subscription or API usage.
Choose your assistant
| Assistant | Setup guide |
|---|---|
| Grok Bot or Grok web | Connect Grok Bot and Grok |
| ChatGPT | Create a custom DoorOps app |
| Claude | Add a custom DoorOps connector |
| Cursor | Configure a remote DoorOps MCP server |
| OpenAI API | Build a DoorOps connection with the Responses API |
These guides cover custom connections. Provider directory publication and approval are separate processes.
Start with your company and role
Tell me which DoorOps company and role I am connected as, and what I can access.
The identity tool is who-am-i-tool. Ask the assistant to check this before reading private records or proposing work.
What you can do
- Find customers, sites, jobs, door assets, quotes and submitted forms.
- Review job history, unassigned work, operational briefs and paperwork awaiting review.
- Prepare permitted customer edits, job changes, scheduling, quote work, timesheets and other employee workflows.
- Review permitted merges, recycle-bin deletions and restores.
Available tools depend on your role and enabled features. Each tool has its own operation and input fields; the server does not expose an arbitrary route executor. Normal validation, scheduling warnings, linked-record blockers and tenant isolation still apply. Some account, payment, credential and larger-file tasks return a link to their normal DoorOps screen.
Confirm before changing anything
Ask the assistant to show the exact records, values, recipients, files and consequences before a creation, edit, send, schedule, merge or deletion. Approve that specific proposal before it acts.
Fixed workflow change tools prepare a five-minute preview. Execution requires the same operation and unchanged preview, with its single-use token. The assistant or client must still obtain real human confirmation: a token or approved flag does not prove consent. Other write tools also require the client to ask before execution.
If an outcome is uncertain, read the current record before retrying. A successful tool response does not prove an email was delivered or a background process finished. Customer-owned records use the normal recycle-bin rules.
Authentication for developers
DoorOps advertises OAuth discovery and dynamic client registration. Use authorization-code flow with PKCE S256 and scope mcp:use; handle refresh and revocation in your client. Callback URIs must be supported by DoorOps. Contact DoorOps if your application's callback needs adding.
MCP OAuth is separate from REST API keys and third-party REST OAuth apps. Never send a DoorOps password in a prompt or use an AI provider's API key as the DoorOps credential.
Follow pagination until discovery is complete, then use the tool definitions returned for that connection. The operate-doorops skill supplies additional operator guidance.
Troubleshooting and disconnecting
| Symptom | Next step |
|---|---|
| No sign-in window | Check the address, OAuth setting and provider permission for custom connections. |
| Signed in, but tools missing | Check the company, role and MCP access; refresh the provider's tool catalogue if supported. |
| HTTP 429 | Wait for Retry-After, then retry once. Avoid repeated parallel discovery or reconnect loops. |
| HTTP 401 or expired session | Reconnect through the provider's sign-in flow. |
| HTTP 403 or a blocked action | Check membership, permissions and enabled features. The assistant cannot override them. |
| Preview expired or details changed | Read the record and prepare a fresh proposal for confirmation. |
Disconnect in the assistant and revoke the DoorOps connection under Settings → Connected apps to stop its access.
The anonymous https://doorops.com/mcp server provides public product information; use the authenticated address above for company records.
Guidance checked 7 October 2026. Provider-specific setup and availability sources are linked in each guide.